CVE-2010-0442

EUVD-2010-0473
The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql
7.4 ≤
𝑥
< 7.4.28
postgresqlpostgresql
8.0 ≤
𝑥
< 8.0.24
postgresqlpostgresql
8.1 ≤
𝑥
< 8.1.20
postgresqlpostgresql
8.2 ≤
𝑥
< 8.2.16
postgresqlpostgresql
8.3 ≤
𝑥
< 8.3.10
postgresqlpostgresql
8.4 ≤
𝑥
< 8.4.3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
postgresql-7.4
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.0
dapper
ignored
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.1
dapper
Fixed 8.1.20-0ubuntu0.6.06
released
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.2
dapper
dne
hardy
ignored
intrepid
dne
jaunty
dne
karmic
dne
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.3
dapper
dne
hardy
Fixed 8.3.10-0ubuntu8.04
released
intrepid
ignored
jaunty
Fixed 8.3.10-0ubuntu9.04
released
karmic
ignored
lucid
dne
maverick
dne
natty
dne
oneiric
dne
postgresql-8.4
dapper
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
Fixed 8.4.3-0ubuntu9.10
released
lucid
Fixed 8.4.3-1
released
maverick
Fixed 8.4.3-1
released
natty
Fixed 8.4.3-1
released
oneiric
Fixed 8.4.3-1
released
Common Weakness Enumeration
References